Blacksheep89 | 10.03.2011 17:06 | Alles klar: Code:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: MICRO-STAR INTERNATIONAL CO.,LTD
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: MICRO-STAR INTERNATIONAL CO.,LTD
System Product Name: MS-7388
Logical Drives Mask: 0x0000000d
Kernel Drivers (total 185):
0x83040000 \SystemRoot\system32\ntkrnlpa.exe
0x83009000 \SystemRoot\system32\halmacpi.dll
0x80BA6000 \SystemRoot\system32\kdcom.dll
0x8362C000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
0x83637000 \SystemRoot\system32\PSHED.dll
0x83648000 \SystemRoot\system32\BOOTVID.dll
0x83650000 \SystemRoot\system32\CLFS.SYS
0x83692000 \SystemRoot\system32\CI.dll
0x8373D000 \SystemRoot\system32\drivers\Wdf01000.sys
0x837AE000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x89002000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x8904A000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x89053000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x8905B000 \SystemRoot\system32\DRIVERS\pci.sys
0x89085000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x89090000 \SystemRoot\System32\drivers\partmgr.sys
0x890A1000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x890B1000 \SystemRoot\System32\drivers\volmgrx.sys
0x890FC000 \SystemRoot\system32\DRIVERS\pciide.sys
0x89103000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x89111000 \SystemRoot\System32\drivers\mountmgr.sys
0x89127000 \SystemRoot\system32\DRIVERS\atapi.sys
0x89130000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x89153000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8915C000 \SystemRoot\system32\drivers\fltmgr.sys
0x89190000 \SystemRoot\system32\drivers\fileinfo.sys
0x89217000 \SystemRoot\System32\Drivers\Ntfs.sys
0x89346000 \SystemRoot\System32\Drivers\msrpc.sys
0x89371000 \SystemRoot\System32\Drivers\ksecdd.sys
0x89384000 \SystemRoot\System32\Drivers\cng.sys
0x893E1000 \SystemRoot\System32\drivers\pcw.sys
0x893EF000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8943D000 \SystemRoot\system32\drivers\ndis.sys
0x894F4000 \SystemRoot\system32\drivers\NETIO.SYS
0x89532000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8963C000 \SystemRoot\System32\drivers\tcpip.sys
0x89785000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x897B6000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x897F5000 \SystemRoot\System32\Drivers\spldr.sys
0x89600000 \SystemRoot\System32\drivers\rdyboost.sys
0x89557000 \SystemRoot\System32\Drivers\mup.sys
0x8962D000 \SystemRoot\System32\drivers\hwpolicy.sys
0x89567000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x89599000 \SystemRoot\system32\DRIVERS\disk.sys
0x895AA000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x895CF000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
0x89411000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x89635000 \SystemRoot\System32\Drivers\Null.SYS
0x89430000 \SystemRoot\System32\Drivers\Beep.SYS
0x89200000 \SystemRoot\System32\drivers\vga.sys
0x891A1000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x891C2000 \SystemRoot\System32\drivers\watchdog.sys
0x895F8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8920C000 \SystemRoot\system32\drivers\rdpencdd.sys
0x893F8000 \SystemRoot\system32\drivers\rdprefmp.sys
0x891CF000 \SystemRoot\System32\Drivers\Msfs.SYS
0x891DA000 \SystemRoot\System32\Drivers\Npfs.SYS
0x891E8000 \SystemRoot\system32\DRIVERS\tdx.sys
0x837BC000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8E234000 \SystemRoot\system32\drivers\afd.sys
0x8E28E000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8E2C0000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8E2C7000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8E2E6000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8E2F4000 \SystemRoot\system32\DRIVERS\serial.sys
0x8E30E000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8E321000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8E331000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8E337000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8E378000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8E382000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8E38C000 \SystemRoot\System32\drivers\discache.sys
0x8E398000 \SystemRoot\System32\Drivers\dfsc.sys
0x8E3B0000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x8E3BE000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8E200000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8E221000 \SystemRoot\system32\DRIVERS\amdppm.sys
0x8EC1A000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x8F12F000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x837C7000 \SystemRoot\System32\drivers\dxgmms1.sys
0x83600000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8F23E000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x8F263000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x8F26D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8F2B8000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8F2C7000 \SystemRoot\system32\DRIVERS\serenum.sys
0x8F2D1000 \SystemRoot\system32\DRIVERS\fdc.sys
0x8F2DC000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8F2F4000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8F301000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8F30A000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x8F317000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x8F329000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8F341000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8F34C000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8F36E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8F386000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8F39D000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8F3B4000 \SystemRoot\system32\DRIVERS\tap0901.sys
0x8F3BB000 \SystemRoot\system32\DRIVERS\hamachi.sys
0x8F3C0000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8F3CD000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8F200000 \SystemRoot\system32\DRIVERS\ks.sys
0x8F3CF000 \SystemRoot\system32\DRIVERS\umbus.sys
0x93C3C000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x93C80000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x93C8A000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x93C9B000 \SystemRoot\system32\drivers\HdAudio.sys
0x93CEB000 \SystemRoot\system32\drivers\portcls.sys
0x93D1A000 \SystemRoot\system32\drivers\drmk.sys
0x94023000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x94304000 \SystemRoot\System32\Drivers\crashdmp.sys
0x94311000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x9431C000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x94325000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x95B90000 \SystemRoot\System32\win32k.sys
0x94336000 \SystemRoot\System32\drivers\Dxapi.sys
0x94340000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x9434B000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x9435E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x94365000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x94367000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x94372000 \SystemRoot\system32\DRIVERS\monitor.sys
0x95DF0000 \SystemRoot\System32\TSDDD.dll
0x95A20000 \SystemRoot\System32\ATMFD.DLL
0x95A70000 \SystemRoot\System32\cdd.dll
0x9437D000 \SystemRoot\system32\drivers\luafv.sys
0x94398000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x943AD000 \SystemRoot\system32\drivers\WudfPf.sys
0x943C7000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x943D7000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x93D33000 \SystemRoot\system32\drivers\HTTP.sys
0x94000000 \SystemRoot\system32\DRIVERS\bowser.sys
0x943EA000 \SystemRoot\System32\drivers\mpsdrv.sys
0x93DB8000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x93C00000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x93DDB000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9BE19000 \SystemRoot\system32\drivers\peauth.sys
0x9BEB0000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9BEBA000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9BEDB000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9BEE8000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9BF37000 \SystemRoot\System32\DRIVERS\srv.sys
0x9BFF2000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x9BE00000 \??\C:\Users\****\AppData\Local\Temp\kwldypoc.sys
0x9BF88000 \SystemRoot\System32\Drivers\fastfat.SYS
0x77610000 \Windows\System32\ntdll.dll
0x47890000 \Windows\System32\smss.exe
0x77850000 \Windows\System32\apisetschema.dll
0x00940000 \Windows\System32\autochk.exe
0x77770000 \Windows\System32\user32.dll
0x77560000 \Windows\System32\rpcrt4.dll
0x77530000 \Windows\System32\imagehlp.dll
0x773D0000 \Windows\System32\ole32.dll
0x77380000 \Windows\System32\Wldap32.dll
0x772B0000 \Windows\System32\msctf.dll
0x77270000 \Windows\System32\ws2_32.dll
0x77760000 \Windows\System32\normaliz.dll
0x77190000 \Windows\System32\kernel32.dll
0x770F0000 \Windows\System32\usp10.dll
0x77040000 \Windows\System32\msvcrt.dll
0x76FB0000 \Windows\System32\oleaut32.dll
0x76F20000 \Windows\System32\clbcatq.dll
0x77750000 \Windows\System32\nsi.dll
0x76F00000 \Windows\System32\imm32.dll
0x76EA0000 \Windows\System32\difxapi.dll
0x76250000 \Windows\System32\shell32.dll
0x76110000 \Windows\System32\urlmon.dll
0x760F0000 \Windows\System32\sechost.dll
0x75F50000 \Windows\System32\setupapi.dll
0x75EB0000 \Windows\System32\advapi32.dll
0x75CB0000 \Windows\System32\iertutil.dll
0x75CA0000 \Windows\System32\psapi.dll
0x75C20000 \Windows\System32\comdlg32.dll
0x75BC0000 \Windows\System32\shlwapi.dll
0x75BB0000 \Windows\System32\lpk.dll
0x75B60000 \Windows\System32\gdi32.dll
0x75A60000 \Windows\System32\wininet.dll
0x75A40000 \Windows\System32\devobj.dll
0x75A10000 \Windows\System32\cfgmgr32.dll
0x759E0000 \Windows\System32\wintrust.dll
0x75990000 \Windows\System32\KernelBase.dll
0x75900000 \Windows\System32\comctl32.dll
0x757E0000 \Windows\System32\crypt32.dll
0x757D0000 \Windows\System32\msasn1.dll
Processes (total 52):
0 System Idle Process
4 System
276 C:\Windows\System32\smss.exe
400 csrss.exe
472 C:\Windows\System32\wininit.exe
480 csrss.exe
520 C:\Windows\System32\services.exe
536 C:\Windows\System32\lsass.exe
544 C:\Windows\System32\lsm.exe
656 C:\Windows\System32\svchost.exe
704 C:\Windows\System32\winlogon.exe
816 C:\Windows\System32\svchost.exe
892 C:\Windows\System32\atiesrxx.exe
952 C:\Windows\System32\svchost.exe
988 C:\Windows\System32\svchost.exe
1036 C:\Windows\System32\svchost.exe
1176 C:\Windows\System32\svchost.exe
1268 C:\Windows\System32\atieclxx.exe
1316 C:\Windows\System32\svchost.exe
1544 C:\Windows\System32\spoolsv.exe
1576 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1596 C:\Windows\System32\svchost.exe
1712 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
1756 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
1788 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
1820 C:\Windows\System32\svchost.exe
1848 C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
1876 C:\Program Files\Hotspot Shield\bin\hsswd.exe
1916 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
1956 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
1968 C:\Windows\System32\conhost.exe
2004 C:\Windows\System32\svchost.exe
1508 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
2904 C:\Windows\System32\svchost.exe
3076 C:\Windows\System32\taskhost.exe
3152 C:\Windows\System32\dwm.exe
3204 C:\Windows\explorer.exe
3300 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
3420 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
3476 C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
1416 C:\Windows\System32\SearchIndexer.exe
2560 C:\Program Files\Windows Media Player\wmpnetwk.exe
3836 C:\Windows\System32\svchost.exe
672 C:\Program Files\Mozilla Firefox\firefox.exe
2448 C:\Program Files\Mozilla Firefox\plugin-container.exe
2328 C:\Windows\System32\SearchProtocolHost.exe
3168 C:\Windows\System32\SearchFilterHost.exe
2480 C:\Windows\explorer.exe
2868 C:\Windows\System32\audiodg.exe
3628 C:\Users\****\Desktop\MBRCheck.exe
1720 C:\Windows\System32\conhost.exe
1172 C:\Windows\System32\dllhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)
PhysicalDrive0 Model Number: HitachiHDT725032VLA380, Rev: V54OA73A
Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
Gmer: Code:
GMER 1.0.15.15530 - hxxp://www.gmer.net
Rootkit scan 2011-03-10 16:44:57
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T1L0-6 Hitachi_HDT725032VLA380 rev.V54OA73A
Running: 1jw9hp18.exe; Driver: C:\Users\****\AppData\Local\Temp\kwldypoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 83083589 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830A8092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EC1B000, 0x2D5378, 0xE8000020]
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 9BFA5000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 9BFA5123 629 Bytes [05, FA, 9B, FE, 05, 34, 05, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 9BFA5399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F 9BFA53FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B 9BFA54AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [742F2494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [742D5624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [742D56E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [742F250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [742E8573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [742E4D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [742E50CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [742E51A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [742E66D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [742E82CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [742E8819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [742E907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [742EE21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3204] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [742E4C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000046 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:3100] 9BFB2F2E
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\SAM041EH9XQB02323_2F_07D8_2D^87585AC7630E6501383E3F73C924A93B@Timestamp 0x1E 0x47 0x9C 0xB1 ...
---- EOF - GMER 1.0.15 ----
OSAM: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 16:53:58 on 10.03.2011
OS: Windows 7 Home Premium Edition (Build 7600), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.15
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\****\AppData\Local\Temp\catchme.sys (File not found)
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys
"kwldypoc" (kwldypoc) - ? - C:\Users\****\AppData\Local\Temp\kwldypoc.sys (Hidden registry entry, rootkit activity | File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found)
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? - (File not found | COM-object registry key not found)
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "{724D43A0-0D85-11D4-9908-00400523E39A}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_20.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10k.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"ICQ7" - "ICQ, LLC." - C:\Program Files\ICQ7.0\ICQ.exe
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} "Easy Photo Print" - "SEIKO EPSON CORPORATION / CyCom Technology Corp." - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
{855F3B16-6D32-4FE6-8A56-BBB695989046} "ICQToolBar" - ? - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} "Easy Photo Print" - "SEIKO EPSON CORPORATION / CyCom Technology Corp." - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{5C255C8A-E604-49b4-9D64-90988571CECB} "{5C255C8A-E604-49b4-9D64-90988571CECB}" - ? - (File not found | COM-object registry key not found)
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AdobeAAMUpdater-1.0" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"LogMeIn Hamachi Ui" - "LogMeIn Inc." - "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"CyberGhost VPN Client" (CGVPNCliSrvc) - "mobile concepts GmbH" - C:\Program Files\S.A.D\CyberGhost VPN\CGVPNCliService.exe
"Hotspot Shield Monitoring Service" (HssWd) - ? - C:\Program Files\Hotspot Shield\bin\hsswd.exe (File found, but it contains no detailed information)
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
"LogMeIn Hamachi 2.0 Tunneling Engine" (Hamachi2Svc) - "LogMeIn Inc." - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"SBSD Security Center Service" (SBSDWSCService) - "Safer Networking Ltd." - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
"Sony Ericsson OMSI download service" (OMSI download service) - ? - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe (File found, but it contains no detailed information)
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"Windows Presentation Foundation Font Cache 4.0.0.0" (WPFFontCache_v0400) - ? - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (File not found)
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
PS: Diesmal hat Gmer ziemlich lang gebraucht, immerhin hats beim 1. versuch geklappt. |